Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

2026-06-13T19:24:13Z978c9317c80f36f663a5f13af73f0302b7923b067590d13c9871a6a76a1c7696
active-exploitationagentjackingai-securityaur-compromisebitlocker-bypasscisa-kevcryptocurrency-launderingeBPF-rootkitfortinetinfostealerlangflowlanggraphmicrosoft-patchespeopleSoftphishingremote-code-executionsplunksupply-chainunauthenticatedzero-day

What happened

Multiple high-impact security stories: Splunk released emergency fixes for a critical unauthenticated file-operation and remote code execution flaw (CVE-2026-20253, CVSS 9.8). Several vulnerabilities are under active exploitation or recently patched, including an Oracle PeopleSoft zero-day used by ShinyHunters (CVE-2026-35273), a Fortinet FortiSandbox command-injection fix (CVE-2026-25089), and an actively exploited Langflow path-traversal RCE (CVE-2026-5027). CISA added new entries to its KEV catalog (e.g., CVE-2026-20245). The news feed also highlights large supply-chain and infrastructure‑f

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
978c9317c80f36f663a5f13af73f0302b7923b067590d13c9871a6a76a1c7696
Enrichment time
2026-06-13T19:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.